Talos Takes: 2025's ransomware trends and zombie vulnerabilities
2026-04-07T20:51:57Z•ad25e779d3fba001168602598f996ce4ae84334f335f672bd26d0e3d2825ba0d
AxiosCanvaEDR-evasionHikVisionLog4jNEXUS-ListenerPHPUnitQilinReact2ShellTP-LinkUAT-10608business-email-compromisecredential-harvestingnpm-compromisephishingransomwaresaas-notification-abusesupply-chainvulnerabilities
What happened
Cisco Talos RSS roundup covering the 2025 Year in Review and multiple active threat trends: rising ransomware activity (including Qilin ransomware and EDR-evasion via msimg32.dll), large-scale credential harvesting campaign tracked as UAT-10608 using the “NEXUS Listener” framework, increased abuse of SaaS notification pipelines for phishing/spam, notable supply-chain incidents (Axios NPM), and disclosure of numerous vendor vulnerabilities (TP-Link, Canva, HikVision) alongside legacy ‘zombie’ vulnerabilities (Log4j, PHPUnit, React2Shell). The feed emphasizes elevated attacker use of identity, E
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- cisco_talos
- Record identifier
- ad25e779d3fba001168602598f996ce4ae84334f335f672bd26d0e3d2825ba0d
- Enrichment time
- 2026-04-07T20:51:57Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.